CVE-2012-4586: Low severity mcafee email and web security vulnerability
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4586?
CVE-2012-4586 is classified as a high severity vulnerability that allows unauthorized access to files by remote authenticated users.
How do I fix CVE-2012-4586?
To fix CVE-2012-4586, upgrade McAfee Email and Web Security to version 5.5 Patch 6 or 5.6 Patch 3, or McAfee Email Gateway to version 7.0 Patch 1 or later.
Who is affected by CVE-2012-4586?
CVE-2012-4586 affects users of McAfee Email and Web Security versions 5.x before 5.5 Patch 6 and 5.6 before Patch 3, as well as McAfee Email Gateway 7.0 before Patch 1.
What are the risks associated with CVE-2012-4586?
The risks of CVE-2012-4586 include unauthorized access to sensitive files, which can lead to data breaches and compromise the security of an organization.
Can CVE-2012-4586 be exploited remotely?
Yes, CVE-2012-4586 can be exploited remotely by authenticated users who can bypass permission settings to access sensitive files.